Lifestyle

EU Cyber Resilience Act Reporting Obligations Begin September 11: Who Must Report, How Fast

On September 11, 2026, the reporting obligations under Article 14 of the EU's Cyber Resilience Act took effect, and ENISA launched its Single Reporting Platform. Based on the European Commission's reporting page, ENISA's press release and FAQ, and the Regulation's text in the Official Journal, this article explains how fast manufacturers must report, where reports go, which obligations already apply, which wait until December 2027, and the fine ceiling in Article 64.

About 14 min read

Original illustration: a clock, an arrow to a report marked with a warning triangle, another arrow to a central platform, which relays it by three lines to three dots for national response teams
Image: Mokaair (© Mokaair)

On September 11, 2026, the reporting obligations under the EU's Cyber Resilience Act (Regulation (EU) 2024/2847) took effect: the European Union Agency for Cybersecurity (ENISA) simultaneously launched its Single Reporting Platform (SRP), letting manufacturers report actively exploited vulnerabilities and severe incidents under Article 14. The Regulation itself splits ‘application’ into three dates, and September 11 is only one of them.

This article was fact-checked on September 17, 2026, drawing on the European Commission's reporting-obligations page, ENISA's launch press release and FAQ, and the Regulation's full text as published in the Official Journal of the European Union. This site has not actually submitted a notification or tested the platform itself; the following does not compare vendors or advise on whether to upgrade a device, and only summarizes the officially published provisions and deadlines.

The Three Dates in Article 71(2): September 11 Is Only Article 14's Turn

Article 71(2) of the Cyber Resilience Act splits ‘application’ into three dates: the Regulation applies in full from December 11, 2027 in principle; Article 14 (manufacturers' reporting obligations) applies earlier, from September 11, 2026; and Chapter IV (Articles 35 to 51, on the notification of conformity assessment bodies) applies earlier still, from June 11, 2026.

Only Article 14 takes effect on September 11, 2026. The European Commission's page states it plainly: manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security from September 11 onward; open-source software stewards take on the same obligation under Article 24(3), but only to the extent they are involved in developing the product, and under Article 71(2) their obligation does not begin until December 11, 2027 — ENISA's FAQ likewise keeps the two starting dates separate.

The Regulation was signed in Strasbourg on October 23, 2024, and published in the Official Journal of the European Union on November 20 of the same year; under the formula in Article 71(1), it entered into force on the twentieth day after publication. ‘Entering into force’ and ‘what the provisions require you to do’ are two different things — every sentence that follows in this article notes whether it is already in effect on September 11 or waits until December 11, 2027.

How Fast a Notification Must Go Out, Once You Know

The clock starts running when the manufacturer becomes aware, not from the moment the vulnerability or incident actually occurs. ENISA's FAQ is explicit: the reporting process starts when a manufacturer — or, once it applies, an open-source software steward — becomes aware of it. Article 3(42) defines an ‘actively exploited vulnerability’ as one for which there is reliable evidence that a malicious actor has exploited it without the system owner's permission — merely knowing a weakness exists does not, on its own, trigger the notification obligation under Article 14(1).

Actively exploited vulnerabilities and severe incidents share the same early-warning and full-notification deadlines, but the formula for the final report differs. Under Article 14(2): without undue delay, and in any case within 24 hours of becoming aware, the manufacturer sends an early warning; within 72 hours, a full notification; and the final report follows within 14 days after a corrective or mitigating measure becomes available. Under Article 14(4), the final report for a severe incident instead falls due within one month after the 72-hour notification itself is submitted — the clock there starts from the notification, not from the moment of awareness, and the 14-day rule does not apply.

Article 14(6) gives the CSIRT one more power: if the CSIRT that received the notification considers it necessary, it may ask the manufacturer for an intermediate report describing a status update — a possible fifth document alongside the early warning, the full notification, and the final report. The European Commission's reporting page condenses these four deadlines into a single sentence.

Compiled from Article 14 of the Cyber Resilience Act; fact-checked September 17, 2026.
StageDeadlineStarting PointLegal Basis
Early warningWithin 24 hoursManufacturer becomes aware of the vulnerability or incidentArticle 14(2)(a), 14(4)(a)
Full notificationWithin 72 hoursManufacturer becomes aware of the vulnerability or incidentArticle 14(2)(b), 14(4)(b)
Final report (vulnerability)Within 14 days of the measure being availableCorrective or mitigating measure becomes availableArticle 14(2)(c)
Final report (incident)Within 1 month of the 72-hour notificationSubmission of the 72-hour full notificationArticle 14(4)(c)

Where a Notification Goes: One Window, Copied to ENISA

A notification is submitted through the Single Reporting Platform only once. Under Article 14(7), the manufacturer submits it through the electronic notification end-point of the CSIRT designated as coordinator for the Member State of its main establishment in the EU, made simultaneously accessible to ENISA; the Commission notes this holds except in particularly exceptional circumstances. ‘Main establishment’ looks first at the Member State where decisions about product security are made; where that cannot be determined, it looks instead at the Member State with the most employees.

For a manufacturer with no main establishment in the EU, Article 14(7) has it work through one of four fallback identities in order: the Member State of the authorised representative handling the largest number of its products, the Member State of the importer placing the largest number of its products on the market, the Member State of the distributor supplying the largest number of its products, or the Member State with the most users. ENISA warns that the consequence of picking the wrong window is not minor: the notification may be invalidated and have to be resubmitted to the correct one.

The CSIRT that receives a notification forwards it to the CSIRTs of the other Member States where the product is on the market, and supplies market surveillance authorities with the information they need — that is the substance of Article 16. Article 71(2)'s list of provisions that apply early covers only Article 14 and Chapter IV; Article 16 is not on it. Even so, both the Commission and ENISA state that the platform was built under Article 16 and has been operating since September 11. In exceptional cases the CSIRT may delay forwarding; the Commission notes that a delegated act adopted on December 11, 2025 sets out the conditions for that delay.

Four-panel diagram: the moment of awareness, notification within 72 hours, submission to the single window, forwarding to other CSIRTs
How the reporting platform receives and relays notifications, compiled from the official pages and the Cyber Resilience Act; fact-checked September 17, 2026. · Image: Mokaair (© Mokaair)

What This Means for Users and Devices Already Sold

Devices already sold are not exempt. ENISA's FAQ states that the Article 14 reporting obligation ‘will apply from 11 September 2026 to all products with digital elements falling within the scope of the CRA, including products that were placed on the market before 11 December 2027.’ For a router, camera, or wearable bought a few years ago — as long as it is sold on the EU market — the manufacturer must report now if it faces an actively exploited vulnerability or a severe incident, without waiting for the Regulation's full application in December 2027.

Article 14(8) requires the manufacturer, once it becomes aware, to inform affected users of the vulnerability or incident, together with any risk-mitigation and corrective measures where necessary, in a structured, machine-readable format where appropriate. The official pages this article consulted set no deadline, language, or channel for that notice. A likely point of confusion: the reporting obligation does not mean ‘a device will get a patch faster’ — that falls under Article 13's maintenance-period rules, which likewise do not apply until December 11, 2027, and the official pages this article consulted do not say that the reporting obligation taking effect will speed up patches.

A reported vulnerability is not automatically made public: under Article 17(5), ENISA adds a publicly known vulnerability to the European vulnerability database (EUVD) only once a corrective or mitigating measure is available and the manufacturer agrees. As for penalties, Article 64 sets a ceiling of up to €15 million, or 2.5% of an offending undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher, for breaches of Articles 13, 14, and the security requirements in Annex I — with the actual rules set by each Member State and notified to the Commission. Article 64 is not among the provisions Article 71(2) lists as applying early; none of the three official pages this article consulted mentions fines, or says whether, between now and December 2027, a breach of Article 14 would be penalized.

How Far the Platform Has Gotten So Far

ENISA describes the platform that just launched as an ‘initial operating capability,’ not a finished product. Its FAQ lists what is still missing: at launch the interface supports English only; there is no application programming interface, so notifications must be submitted through the platform's own interface; and voluntary reporting under Article 15 — covering vulnerabilities, threats, incidents, and near-misses — is not yet available, so the platform currently accepts only the mandatory notifications required under Article 14. ENISA says voluntary reporting will be introduced in a ‘future phase’; for the application programming interface and additional language versions, it says only that they may be considered, or will be reviewed, in the next phase — neither comes with a timetable.

The platform is also not a channel for consumer complaints: the current release accepts only the mandatory notifications manufacturers submit under Article 14, and a submission from someone who is not a manufacturer may be marked invalid. ENISA also openly acknowledges a known flaw: the 72-hour countdown timer actually shows a due time 48 hours after the 24-hour early warning is submitted, so in some cases a notification shows as overdue before 72 hours have actually elapsed since the manufacturer became aware; ENISA stresses that the timer's display does not replace the legal obligation itself.

There are also identity limits on who may submit a notification: each manufacturer may have only one ‘Primary’ designated representative (Primary AR) and up to 20 ‘Secondary’ designated representatives (Secondary ARs), who must log in with an EU Login account protected by multi-factor authentication — the platform currently has no additional corporate-identity verification mechanism. The Primary and Secondary representatives of the same manufacturer can all see that manufacturer's notifications, regardless of who originally submitted them; only unsubmitted drafts stay in each representative's own account. The official pages this article consulted do not disclose how many notifications, or how many registered manufacturers, the platform has had since launch, so this article does not state either figure.

Frequently asked questions

My device wasn't bought in the EU — does this reporting obligation have anything to do with me?

Article 2 of the Cyber Resilience Act sets its scope as connected products ‘made available on the market’ in the EU with a connection to a device or network. As of the official pages this article consulted on September 17, 2026, none of them says anything specifically about Taiwan or markets outside the EU; Article 14(7) only addresses which country's window a notification is sent to (including how that is decided when a manufacturer has no main establishment in the EU), which has nothing to do with where the user is located. What decides whether the rule reaches a given case is still the market scope in Article 2. This article can only cite how the provisions themselves define that scope — it cannot tell a reader whether their own device counts.

I found a vulnerability in my own device — can I report it through this platform?

No. ENISA's FAQ states plainly that the current version of the platform accepts only the mandatory notifications manufacturers submit under Article 14; a notification from someone who is not a manufacturer may be flagged as invalid by the platform, and ENISA suggests contacting your own country's CSIRT directly instead. Article 15 was designed to give anyone a voluntary reporting channel, but ENISA says this feature is not yet available in the platform's current version.

Once a notification is made, will I find out what happened to my device?

The official pages this article consulted set no specific notification deadline. Article 14(8) requires the manufacturer, once it becomes aware, to inform affected users — and where appropriate all users — of the vulnerability or incident, and, where necessary, of any mitigation or corrective measures they can take; but the provision only states that a CSIRT may notify users on the manufacturer's behalf if the manufacturer fails to inform them ‘in a timely manner’ — it does not set how quickly notice must go out, nor its language or channel. The vulnerability itself is not automatically made public either: under Article 17(5), ENISA adds a publicly known vulnerability to the European vulnerability database only once a corrective measure is available and the manufacturer agrees.

Does the manufacturer still have to report an older device I've had for years?

Based on the official pages, yes. ENISA's FAQ states that the Article 14 reporting obligation ‘will apply from 11 September 2026 to all products with digital elements falling within the scope of the CRA, including products that were placed on the market before 11 December 2027.’ That differs from the Regulation's usual transitional rule, under which an older product only has to meet the new requirements if it is later ‘substantially modified’ — the reporting obligation is not limited that way, and applies regardless of how old the product is.

What else changes after December 11, 2027?

At that point the Cyber Resilience Act applies in full, in principle, including parts this article has not covered in detail: Article 13(8) requires manufacturers to set a support period of at least five years — unless the product's expected use is shorter than five years, in which case the support period matches that expected use instead; Article 13(9) requires every security update issued during the support period to remain available for at least ten years after release, or for the rest of the support period, whichever is longer; and Article 24(3) extends the same reporting obligation to open-source software stewards, limited to the extent they are involved in developing the product. The official pages this article consulted group all of this under the Regulation's main obligations, distinct from the Article 14 reporting obligation that is already in effect.

How much can a company be fined for failing to report?

Article 64 sets a ceiling: up to €15 million, or 2.5% of an offending undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher, for breaches of Articles 13, 14, and the security requirements in Annex I — but the actual penalty rules are set by each Member State and notified to the European Commission. Article 64 itself is not among the provisions Article 71(2) lists as applying early, and none of the three official pages this article consulted mentions fines or says whether — or how — a breach of Article 14 would be penalized between now and December 11, 2027.

Latest travel guides

Sources

Lifestyle